<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; .net security</title>
	<atom:link href="http://www.darknet.org.uk/tag/net-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>FxCop &#8211; .NET Framework Security Analysis Tool</title>
		<link>http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/</link>
		<comments>http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 11:10:51 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[.net code analysis]]></category>
		<category><![CDATA[.net code scanner]]></category>
		<category><![CDATA[.net code security]]></category>
		<category><![CDATA[.net framework security]]></category>
		<category><![CDATA[.net fxcop]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[fxcop]]></category>
		<category><![CDATA[microsoft .net]]></category>
		<category><![CDATA[microsoft fxcop]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2627</guid>
		<description><![CDATA[FxCop is an application that analyzes managed code assemblies (code that targets the .NET Framework common language runtime) and reports information about the assemblies, such as possible design, localization, performance, and security improvements. Many of the issues concern violations of the programming and design rules set forth in the Design Guidelines, which are the Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>FxCop is an application that analyzes managed code assemblies (code that targets the .NET Framework common language runtime) and reports information about the assemblies, such as possible design, localization, performance, and security improvements. Many of the issues concern violations of the programming and design rules set forth in the Design Guidelines, which are the Microsoft guidelines for writing robust and easily maintainable code by using the .NET Framework.</p>
<p>FxCop is intended for class library developers. However, anyone creating applications that should comply with the .NET Framework best practices will benefit. FxCop is also useful as an educational tool for people who are new to the .NET Framework or who are unfamiliar with the .NET Framework Design Guidelines.</p>
<p>FxCop is designed to be fully integrated into the software development cycle and is distributed as both a fully featured application that has a graphical user interface (FxCop.exe) for interactive work, and a command-line tool (FxCopCmd.exe) suited for use as part of automated build processes or integrated with Microsoft Visual Studio® .NET as an external tool. </p>
<p>To get FxCop you need to install &#8220;<a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=35aeda01-421d-4ba5-b44b-543dc8c33a20&#038;displaylang=en">Windows SDK for Windows 7.1</a>&#8220;. In the release notes you will find this message:</p>
<blockquote><p>6.3.6 FXCop Setup is Now Located Under the Window SDK “\Bin” Directory.<br />
The installer for FXCop, fxcopsetup.exe, is now located in Program Files\Microsoft SDKs\Windows\v7.1\Bin\FXCop. </p></blockquote>
<p></p>
<p>Or read more <a href="http://msdn.microsoft.com/en-us/library/bb429476%28VS.80%29.aspx">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=FxCop+%E2%80%93+.NET+Framework+Security+Analysis+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2627+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/&amp;t=FxCop+%E2%80%93+.NET+Framework+Security+Analysis+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/&amp;title=FxCop+%E2%80%93+.NET+Framework+Security+Analysis+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/&amp;title=FxCop+%E2%80%93+.NET+Framework+Security+Analysis+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/&amp;title=FxCop+%E2%80%93+.NET+Framework+Security+Analysis+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/&amp;title=FxCop+%E2%80%93+.NET+Framework+Security+Analysis+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F07%2Ffxcop-net-framework-security-analysis-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/07/fxcop-net-framework-security-analysis-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP CodeCrawler &#8211; Static Code Review Tool</title>
		<link>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/</link>
		<comments>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 11:07:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[.net code review]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[code scanning tool]]></category>
		<category><![CDATA[code security]]></category>
		<category><![CDATA[code testing]]></category>
		<category><![CDATA[code-audit]]></category>
		<category><![CDATA[codecrawler]]></category>
		<category><![CDATA[development security]]></category>
		<category><![CDATA[J2EE-security]]></category>
		<category><![CDATA[JAVA-security]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[owasp codecrawler]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[static code analysis tool]]></category>
		<category><![CDATA[static code review]]></category>
		<category><![CDATA[static code review tool]]></category>
		<category><![CDATA[static code security tool]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2510</guid>
		<description><![CDATA[CodeCrawler is a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It&#8217;s a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project. It provides automatic STRIDE classification a very simple DREAD calculator and few minor [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CodeCrawler is a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It&#8217;s a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project.</p>
<p>It provides automatic STRIDE classification a very simple DREAD calculator and few minor utilities. Direct links to WAST 2.0 Threat Classification, Secure Java Development Guidelines and OWASP Tools are also part of the package. </p>
<p><strong>Requirements</strong></p>
<ul>
<li>.NET Framework 3.5 (Service Pack 1)</li>
<li>Visual Studio 2008</li>
<li>Windows Platform</li>
</ul>
<p>You can download CodeCrawler here:</p>
<p><a href="http://codecrawler.codeplex.com/releases/view/39345#DownloadId=102703">CODECRAWLER_2.5_RELEASE.zip</a></p>
<p></p>
<p>Or read more <a href="http://codecrawler.codeplex.com/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2510+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;t=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/&amp;title=OWASP+CodeCrawler+%E2%80%93+Static+Code+Review+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F03%2Fowasp-codecrawler-static-code-review-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/03/owasp-codecrawler-static-code-review-tool/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Microsoft CAT.NET v1.1.1.9 &#8211; Binary Code Analysis Tool .NET</title>
		<link>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/</link>
		<comments>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 09:39:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[.net auditing tool]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[binary code analysis]]></category>
		<category><![CDATA[binary-analysis]]></category>
		<category><![CDATA[cat.net]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[visual studio ide]]></category>
		<category><![CDATA[Visual-Studio]]></category>
		<category><![CDATA[windows-security]]></category>
		<category><![CDATA[xpath injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2321</guid>
		<description><![CDATA[CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection. CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection.</p>
<p>CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual Basic .NET, J#) application you are developing. It does so by scanning the binary and/or assembly of the application, and tracing the data flow among its statements, methods, and assemblies.</p>
<p>This includes indirect data types such as property assignments and instance tainting operations. The engine works by reading the target assembly and all reference assemblies used in the application — module-by-module — and then analyzing all of the methods contained within each. It finally displays the issues its finds in a list that you can use to jump directly to the places in your application’s source code where those issues were found.</p>
<p>The following rules are currently support by this version of the tool</p>
<ul>
<li>Cross Site Scripting</li>
<li>SQL Injection</li>
<li>Process Command Injection</li>
<li>File Canonicalization</li>
<li>Exception Information</li>
<li>LDAP Injection</li>
<li>XPATH Injection</li>
<li>Redirection to User Controlled Site</li>
</ul>
<p><strong>System Requirements</strong></p>
<p>Supported Operating Systems: Windows Vista; Windows XP</p>
<p>OS: XP, Vista Software: .NET Framework 2.0, Visual Studio 2005 or 2008. </p>
<p>You can download CAT.NET here:</p>
<p><a href="http://www.microsoft.com/downloads/info.aspx?na=90&#038;p=&#038;SrcDisplayLang=en&#038;SrcCategoryId=&#038;SrcFamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f3%2f3%2f4%2f334E8A84-0F1B-4E3C-AF5F-99DA8AE0601F%2fCATNETx32.msi">CATNETx32.msi</a></p>
<p></p>
<p>Or read more <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;displaylang=en">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2321+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;t=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fmicrosoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox Blocks Microsoft .NET Framework Assistant Add-on</title>
		<link>http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/</link>
		<comments>http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/#comments</comments>
		<pubDate>Mon, 19 Oct 2009 09:57:18 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[.net framework assistant]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox .net add-on]]></category>
		<category><![CDATA[firefox add-on security]]></category>
		<category><![CDATA[firefox blocklist]]></category>
		<category><![CDATA[firefox plug-in blocklist]]></category>
		<category><![CDATA[firefox-security]]></category>
		<category><![CDATA[firefox-vulnerability]]></category>
		<category><![CDATA[hacking-firefox]]></category>
		<category><![CDATA[ie8 vulnerability]]></category>
		<category><![CDATA[windows presentation foundation]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2196</guid>
		<description><![CDATA[This is an interesting development, I noticed the pop-up on my Firefox yesterday. The reason however wasn&#8217;t security it was &#8216;instability&#8217;. It&#8217;s a fair move by Mozilla though as the add-on can cause security vulnerabilities in Firefox outside of their control. They can&#8217;t fix the software, so the best thing they can do to ensure [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>This is an interesting development, I noticed the pop-up on my Firefox yesterday. The reason however wasn&#8217;t security it was &#8216;instability&#8217;.</p>
<p>It&#8217;s a fair move by Mozilla though as the add-on can cause security vulnerabilities in Firefox outside of their control. They can&#8217;t fix the software, so the best thing they can do to ensure user safety is to block it.</p>
<p>Compounded with the fact it&#8217;s extremely hard for users to remove the add-on themselves the block is a good idea.</p>
<blockquote><p>Mozilla late Friday blocked the Microsoft-made software that had put Firefox users at risk from attack.</p>
<p>The two-part Microsoft component &#8212; an add-on dubbed &#8220;.NET Framework Assistant&#8221; and a plug-in named &#8220;Windows Presentation Foundation&#8221; &#8212; have been blocked by Mozilla as a precautionary measure, said Mike Shaver, the company&#8217;s head of engineering.</p>
<p>&#8220;Because of the difficulties some users have had entirely removing the add-on, and because of the severity of the risk it represents if not disabled, we contacted Microsoft today to indicate that we were looking to disable the extension and plug-in for all users via our blocklisting mechanism,&#8221; Shaver said in an announcement posted Friday night to the company&#8217;s security blog . </p></blockquote>
<p>The annoying thing is these add-ons are installed in Firefox without any kind of prompt or permission given by the user.</p>
<p>Microsoft pushed them out with the .NET Framework 3.5 Service Pack 1 (SP1) update in February this year, so our browsers have been vulnerable since then.</p>
<p>The software was almost impossible to remove without some registry hacking, <a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&#038;FamilyID=cecc62dc-96a7-4657-af91-6383ba034eab">Microsoft did remedy this later</a> &#8211; but still how many people would know?</p>
<blockquote><p>Mozilla maintains an add-on/plug-in blocking list that automatically bars risky software from being used by Firefox. The open-source company first used the blocker in 2007. Mozilla has used the tool only nine times, including Friday&#8217;s blocking of the Microsoft add-on and plug-in. In May 2008, for example, Mozilla added a Vietnamese language pack for Firefox to the blocking list when the pack was found to contain a worm.</p>
<p>According to Shaver, Microsoft gave Mozilla the go-ahead to block the .Net Framework Assistant and the Windows Presentation Foundation.</p>
<p>Last week, Microsoft&#8217;s security team acknowledged that its software &#8212; which had been silently installed in Firefox as far back as February 2009 &#8212; contained a critical vulnerability that could be used by hackers to hijack Windows PCs. The same vulnerability also affected all versions of Internet Explorer (IE), including the newest version, IE8. </p></blockquote>
<p>Thankfully Firefox has the blocklist functionality and they have been aggressively moving towards ensuring 3rd party additions are also secure and don&#8217;t comprise the integrity of the platform.</p>
<p>Last month they warned users with out of date Flash plugins to update.</p>
<p>Firefox 3.6 will be even more aggressive in this aspect warning users when they visit a site that relies on one or more outdated add-ons.</p>
<p></p>
<p>Source: <a href="http://www.networkworld.com/news/2009/101909-mozilla-blocks-microsofts-sneaky-firefox.html">Network World</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Firefox+Blocks+Microsoft+.NET+Framework+Assistant+Add-on+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2196+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/&amp;t=Firefox+Blocks+Microsoft+.NET+Framework+Assistant+Add-on" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/&amp;title=Firefox+Blocks+Microsoft+.NET+Framework+Assistant+Add-on" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/&amp;title=Firefox+Blocks+Microsoft+.NET+Framework+Assistant+Add-on" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/&amp;title=Firefox+Blocks+Microsoft+.NET+Framework+Assistant+Add-on" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/&amp;title=Firefox+Blocks+Microsoft+.NET+Framework+Assistant+Add-on" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F10%2Ffirefox-blocks-microsoft-net-framework-assistant-add-on%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/10/firefox-blocks-microsoft-net-framework-assistant-add-on/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Hacker Develops Tool To Hide Malware in .NET Framework</title>
		<link>http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/</link>
		<comments>http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/#comments</comments>
		<pubDate>Tue, 21 Apr 2009 16:34:32 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[.net exploit]]></category>
		<category><![CDATA[.net malware tool]]></category>
		<category><![CDATA[.net rootkit]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[.net vulnerability]]></category>
		<category><![CDATA[.Net-Sploit]]></category>
		<category><![CDATA[hacking .net]]></category>
		<category><![CDATA[hiding malware]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[malware tool]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1724</guid>
		<description><![CDATA[Once again something is wrong with part of the Microsoft suite of software and once again they are denying it&#8217;s anything to do with them. This time a researcher has developed a rootkit style infection tool aimed at the .Net framework. Most modern computers come with .Net of some description installed so this could be [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Once again something is wrong with part of the <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> suite of software and once again they are denying it&#8217;s anything to do with them.</p>
<p>This time a researcher has developed a rootkit style infection tool aimed at the .Net framework.</p>
<p>Most modern computers come with .Net of some description installed so this could be quite a widespread threat, especially if it gets into the hands of the bad guys and they use it for something like <a href="http://www.darknet.org.uk/tag/conficker/">Conficker</a>.</p>
<blockquote><p>A computer security researcher has released an upgraded tool that can simplify the placement of difficult-to-detect malicious software in Microsoft&#8217;s .Net framework on Windows computers.</p>
<p>The tool, called .Net-Sploit 1.0, allows for modification of .Net, a piece of software installed on most Windows machines that allows the computers to execute certain types of applications.</p>
<p>Microsoft makes a suite of developer tools for programmers to write applications compatible with the framework. It offers developers the advantage of writing programs in several different high-level languages that will all run on a PC.</p>
<p>.Net-Sploit allows a hacker to modify the .Net framework on targeted machines, inserting rootkit-style malicious software in a place untouched by security software and where few security people would think to look, said Erez Metula, the software security engineer for 2BSecure who wrote the tool.</p></blockquote>
<p>It an interesting attack vector, attacking a different part of the OS that isn&#8217;t usually targeted. It offers better protection from AV software and from being found and it&#8217;s pretty much guaranteed all Windows computers will have .Net installed.</p>
<p>I&#8217;d guess some pretty interesting stuff can be gathered by tapping into .Net.</p>
<blockquote><p>.Net-Sploit essentially lets an attacker replace a legitimate piece of code within .Net with a malicious one. Since some applications depend on parts of the .Net framework in order to run, it means the malware can affect the function of many applications.</p>
<p>For example, an application that has an authentication mechanism could be attacked if the tampered .Net framework were to intercept user names and passwords and send them to a remote server, Metula said.</p>
<p>.Net-Sploit automates some of the arduous coding tasks necessary to corrupt the framework, speeding up development of an attack. For example, it can help pull a relevant DLL (dynamic link library) from the framework and deploy the malicious DLL.</p>
<p>Metula said that an attacker would already have to have control of a machine before his tool could be used. The advantage of corrupting the .Net framework is that an attacker could clandestinely maintain control over the machine for a long time.</p>
<p>It could potentially be abused by rogue system administrators, who could abuse their access privileges to deploy so-called &#8220;backdoors&#8221; or malware than enables remote access, Metula said.</p></blockquote>
<p>Of course the disadvantage is you already need to have control over the machine to execute this kind of attack, I guess it&#8217;s for when you&#8217;ve hacked the machine and you want to keep control or gather more data.</p>
<p>Metula has <a href="http://applicationsecurity.co.il/english/NETFrameworkRootkits/tabid/161/Default.aspx">published a white paper</a> on the technique as well as the latest version of .Net-Sploit.</p>
<p></p>
<p>Source: <a href="http://www.cio.com/article/print/489729">CIO</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Hacker+Develops+Tool+To+Hide+Malware+in+.NET+Framework+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1724+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/&amp;t=Hacker+Develops+Tool+To+Hide+Malware+in+.NET+Framework" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/&amp;title=Hacker+Develops+Tool+To+Hide+Malware+in+.NET+Framework" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/&amp;title=Hacker+Develops+Tool+To+Hide+Malware+in+.NET+Framework" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/&amp;title=Hacker+Develops+Tool+To+Hide+Malware+in+.NET+Framework" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/&amp;title=Hacker+Develops+Tool+To+Hide+Malware+in+.NET+Framework" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F04%2Fhacker-develops-tool-to-hide-malware-in-net-framework%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/hacker-develops-tool-to-hide-malware-in-net-framework/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

